Skip to main content
Version: 1.0.0

Assessment Playbooks

Use these playbooks when you are working inside the Compliance and Assessments module. They keep the steps, screenshots, questions, and cross-module impact close to the module instead of forcing administrators into a separate process menu.

Run an Assessment from Start to Closure

Use this when a compliance manager creates an assessment and control owners must complete control responses.

  1. Open Compliance and Assessments.
  2. Confirm the framework is active and the controls are in scope.
  3. Click Create Assessment.
  4. Select the framework, assessment type, owner, planned dates, and recurrence if needed.
  5. Save the assessment.
  6. Open the assessment and click Start if it is still Draft.
  7. Open the Controls tab.
  8. Assign controls to owners by selected controls or domain.
  9. Ask owners to update status, findings, recommendations, maturity when applicable, and evidence.
  10. Review all Non-Compliant and Partially Compliant controls.
  11. Create issues for concrete remediation work.
  12. Review auto-created compliance risks for Non-Compliant controls.
  13. Submit the assessment for review.
  14. Reviewer approves or sends it back.
  15. Close or retain the assessment according to the assessment workflow.

Expected result: assessment score, progress, evidence, findings, issues, risks, comments, activity, and approval history are traceable.

Convert a Failed Control into Follow-Up Work

Use this when a control response is Non-Compliant or Partially Compliant.

SituationCorrect Follow-Up
There is a concrete corrective taskCreate an issue.
There is exposure or uncertaintyCreate or review a risk.
The gap was found during auditLink or create an audit finding.
The organization accepts the gap temporarilyRecord acceptance or exception according to policy.

Recommended sequence:

  1. Open the failed assessment control.
  2. Confirm the finding and recommendation are clear.
  3. Check whether evidence is missing, weak, expired, or contradicted.
  4. Create an issue when remediation has a known owner and due date.
  5. Review generated compliance risks for Non-Compliant controls.
  6. Link existing risks when the failed control affects residual exposure.
  7. Do not report closure until the follow-up record has owner, due date, evidence expectation, and status.

Audit Finding to Targeted Reassessment

Use this when an auditor creates a finding against an exact assessment control.

  1. Auditor links the audit to the source assessment.
  2. Auditor links the finding to the exact failed assessment control.
  3. Material findings must be linked to an issue or risk.
  4. Remediation owner uploads evidence and submits the finding for verification.
  5. Auditor verifies the remediation.
  6. The platform marks the linked assessment control as requiring reassessment.
  7. The control status is reset to Not Assessed.
  8. A targeted reassessment due date is set.
  9. If the parent assessment was Completed or Closed, it is reopened to In Progress.
  10. Control owner reassesses only the affected control and uploads updated evidence.
  11. Saving the reassessment clears the reassessment flag.
  12. Linked risks, issues, or treatment actions can then be updated or closed.

This is the preferred enterprise flow. Do not create a full new assessment when only one verified audit finding requires retesting.

Screenshots

Assessment List

Assessments list

Framework Source

Frameworks

FAQ

QuestionAnswer
Does progress mean compliance?No. Progress means controls have responses. Score reflects compliance.
Can a completed assessment be edited?Normally no. A verified audit finding can reopen only the affected control for targeted reassessment.
Should every failed control create a risk?Not always. Use issues for known corrective work and risks for exposure or uncertainty.
Should audit remediation create a new assessment?No, use targeted reassessment unless the business wants a full new cycle.
When can linked risk be closed?After remediation evidence, auditor verification where applicable, and reassessment support the corrected control state.